Trust & Security

How we protect customer data, who is behind the service, and which sub-processors we share data with.

The legal entity

Company
LMTS DEVELOPMENT LTD
Companies House number
17148125
Director
Panikkos Panayiotou

The data on this page is the public commercial signal we expose to Google and Yandex for E-E-A-T and commercial-trust ranking factors. See Companies House for the canonical record.

Compliance

StandardStatus
SOC 2 Type IIIn audit, expected Q3
GDPRDPA available on request
HIPAAAvailable on Enterprise (signed BAA)
ISO 27001On the roadmap, 2027

Sub-processors

We update this list and email customers in advance of any new processor that handles personal data.

VendorPurpose
StripePayments
CloudflareCDN, DNS, WAF
VercelMarketing site hosting
Fly.io / GCPCompute (browser pool)
SupabaseAuth, database, storage
PostHogProduct analytics
2Captcha / CapSolver / AntiCaptchaCAPTCHA solving (rotation)
Bright Data / Oxylabs / IPRoyalResidential proxies (rotation)
Better StackLogs and uptime monitoring
SentryError tracking

Security practices

  • Ephemeral browser containers — destroyed at session end, no persistent disk for customer data unless you explicitly opt in to BYO storage.
  • API keys hashed at rest, scoped per environment (test / live), rotateable in the dashboard.
  • All traffic over TLS 1.2+; HSTS preloaded; mTLS available on Enterprise.
  • Cloudflare WAF in front of the marketing site; Fastify rate-limits in front of the gateway.
  • Annual third-party penetration test starting with the first SOC2 Type II window.
  • Responsible-disclosure program: security@browserforhire.com.